Skip to content

Commit a45a0ab

Browse files
Sashant8m
authored andcommitted
Fix NULL dereference in QUIC address validation
QUIC server crashes when address validation (RFC 9000, Section 8.1) is disabled and client sends initial packet with invalid token. Issue reported and fix submitted by Sunwoo Lee (KENTECH), Hyuk Lim (KENTECH) and Seunghyun Yoon (KENTECH) Fixes CVE-2026-42764 Reviewed-by: Norbert Pocs <norbertp@openssl.org> Reviewed-by: Tomas Mraz <tomas@openssl.foundation> MergeDate: Mon Jun 8 14:50:48 2026 (cherry picked from commit e74289062ca6ff778807aa79c03eae4cfc9635b7)
1 parent 131145d commit a45a0ab

1 file changed

Lines changed: 4 additions & 2 deletions

File tree

‎ssl/quic/quic_port.c‎

Lines changed: 4 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1675,8 +1675,10 @@ static void port_default_packet_handler(QUIC_URXE *e, void *arg,
16751675
* forget qrx so channel can create a new one
16761676
* with valid initial encryption level keys.
16771677
*/
1678-
qrx_src = qrx;
1679-
qrx = NULL;
1678+
if (qrx != NULL) {
1679+
qrx_src = qrx;
1680+
qrx = NULL;
1681+
}
16801682
}
16811683

16821684
port_bind_channel(port, &e->peer, &hdr.dst_conn_id,

0 commit comments

Comments
 (0)